GCP Professional Cloud Security Engineer Practice Question

Your organization uses an on-premises Active Directory that is synchronized to Azure AD. Security policy forbids storing user passwords outside the corporate IdP, yet engineers must sign in to the Google Cloud Console and the gcloud CLI with their existing user principal names (UPNs). A Cloud Identity tenant has already been created and the corporate DNS domain is verified. Which approach meets these requirements while keeping administrative effort low?

  • Enable password synchronization in Google Cloud Directory Sync so hashed passwords are copied from Active Directory to Cloud Identity, allowing users to authenticate directly with Google.

  • Generate a user-managed service account key for every engineer and instruct them to run gcloud auth activate-service-account when they need console or CLI access.

  • Create a Workload Identity Federation pool that trusts Azure AD and have engineers use gcloud auth login --workforce-pool-user-token; no changes to SAML settings are required.

  • Configure Cloud Identity for SAML 2.0 single sign-on with Azure AD, setting the UPN as the SAML Subject (NameID) and enabling Google-initiated (SP-initiated) SSO for the verified domain.

GCP Professional Cloud Security Engineer
Configuring Access
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot